
Privacy Policy
PRIVACY POLICY
Last Updated: June 24, 2026
1. INTRODUCTION
Pylant Risk is a business name operated by Pylant Advisory LLC.
This Privacy Policy explains how Pylant Advisory LLC, doing business as Pylant Risk (“Pylant Risk,” “we,” “our,” or “us”), collects, uses, discloses, retains, and protects personal information when you:
Visit our website;
Submit a contact form;
Communicate with us by email, telephone, video call, or other means;
Request information about our services;
Engage us to provide compliance-risk, investigative, remediation, complaint-coordination, or crisis-response services;
Provide information relating to a compliance, regulatory, commercial, or investigative matter; or
Otherwise interact with us.
This Privacy Policy applies to information that identifies, relates to, describes, or can reasonably be associated with an individual.
Information relating solely to a company, organization, product, marketplace listing, or other legal entity may not constitute personal information unless it identifies or relates to an individual.
2. WHO WE ARE
Business name: Pylant Risk
Legal entity: Pylant Advisory LLC
Website: www.pylantrisk.com
Email: contact@pylantrisk.com
Business address: 30 N Gould St, Ste N, Sheridan, WY 82801, United States
Where applicable data-protection law applies, Pylant Advisory LLC generally acts as the controller of personal information collected through this website and through our business activities.
3. INFORMATION WE COLLECT
We seek to collect only information reasonably necessary for the relevant business, compliance, investigative, contractual, legal, or security purpose.
A. Information You Voluntarily Provide
We may collect information that you voluntarily provide through our website, contact forms, email, calls, meetings, or other communications, including:
Name;
Business email address;
Telephone number;
Company or organization name;
Job title or professional role;
Country or business location;
Information included in an inquiry or message;
Details of a compliance concern, commercial risk, investigation request, or remediation matter;
Product, seller, supplier, manufacturer, distributor, importer, exporter, or marketplace information;
Documents, screenshots, photographs, correspondence, invoices, test reports, certificates, product records, or other evidence;
Contracting, billing, and payment-related information; and
Any other information you choose to provide.
You are not required to provide personal information merely to browse the public pages of this website.
However, certain information may be required if you request a response, assessment, proposal, or service.
B. Information Processed During Compliance and Risk-Management Work
When we evaluate or perform a compliance, investigative, remediation, complaint-coordination, or crisis-response matter, we may process information concerning:
Business owners, directors, officers, employees, agents, and representatives;
Sellers, suppliers, manufacturers, distributors, importers, exporters, and fulfillment providers;
Professional contacts and authorized representatives;
Marketplace accounts, listings, storefronts, websites, and public profiles;
Product packaging, labels, manuals, certification records, shipment records, and product documentation;
Public regulatory, certification, customs, corporate, court, or administrative records;
Public advertisements, product claims, environmental claims, commercial statements, and online content;
Communications supplied by clients, counterparties, professional advisers, or other relevant persons;
Test-buy transactions and associated seller, payment, delivery, or fulfillment information; and
Other information reasonably relevant to the matter.
Some of this information may be obtained from publicly available sources or from third parties rather than directly from the individual concerned.
C. Limited Technical Information
When you visit this website, Framer and other infrastructure, hosting, security, or network providers may automatically process limited technical information necessary to:
Deliver website content;
Operate and maintain the website;
Protect the website against fraud, misuse, or security threats;
Diagnose technical errors;
Maintain service reliability; and
Produce aggregated or privacy-oriented website statistics.
Depending on the provider and technical circumstances, this information may include:
IP address;
Browser and device type;
Operating system;
Date and time of access;
Pages visited;
Referring page or website;
Approximate country or region derived from technical network information;
Basic performance and diagnostic information; and
Security, server, and error logs.
We do not use this information to create individual advertising profiles, conduct cross-site behavioral tracking, or identify ordinary website visitors.
D. Information From Other Sources
We may receive relevant information from:
Clients and prospective clients;
Business partners;
Attorneys and professional advisers;
Laboratories and certification providers;
Marketplaces and e-commerce platforms;
Public authorities and regulatory databases;
Corporate registries;
Customs, court, and administrative records;
Public websites and social-media pages;
Research and data providers;
Suppliers, manufacturers, distributors, and other commercial parties; and
Individuals reporting, responding to, or affected by a compliance concern.
4. HOW WE USE PERSONAL INFORMATION
We may use personal information to:
Respond to inquiries and communications;
Assess whether we are able and willing to accept a matter;
Prepare proposals, engagement terms, and service arrangements;
Conduct compliance intelligence and commercial-risk assessments;
Investigate suspected compliance, regulatory, marketplace, product, or advertising violations;
Verify identities, business relationships, products, claims, certifications, and records;
Organize, preserve, review, and analyze evidence;
Conduct or coordinate test buys, product reviews, and documentation checks;
Prepare risk assessments, reports, findings, and corrective-action recommendations;
Coordinate marketplace complaints, regulatory submissions, or other authorized reports;
Communicate with clients, platforms, authorities, counterparties, attorneys, laboratories, and professional advisers;
Support remediation, negotiation, dispute resolution, crisis response, and public-relations activities;
Conduct conflict, sanctions, fraud, restricted-party, or commercial-risk screening;
Establish, administer, and enforce contracts;
Process payments and maintain accounting records;
Protect our legal rights, personnel, systems, clients, and business operations;
Detect or prevent fraud, abuse, security incidents, or unlawful activity;
Improve our website, services, internal procedures, and communications;
Comply with legal, regulatory, tax, accounting, sanctions, and recordkeeping obligations;
Establish, exercise, or defend legal claims; and
Maintain records necessary to document our work and decisions.
We do not sell personal information for monetary consideration.
5. LEGAL BASES FOR PROCESSING
Where applicable law requires us to identify a legal basis, we may process personal information on one or more of the following grounds.
A. Contract and Pre-Contractual Steps
Processing may be necessary to:
Respond to a request for services;
Prepare a proposal or engagement;
Enter into an agreement; or
Perform our contractual obligations.
B. Legitimate Interests
We may process personal information where reasonably necessary for legitimate business interests, including:
Responding to professional and commercial inquiries;
Evaluating and performing compliance-risk services;
Investigating suspected violations or commercial risks;
Protecting legal, commercial, and regulatory interests;
Preventing fraud, misuse, and security threats;
Managing business and professional relationships;
Maintaining accurate business records; and
Establishing, exercising, or defending legal claims.
Where required, we consider whether our interests are overridden by the rights and interests of affected individuals.
C. Legal Obligations
We may process information where necessary to comply with:
Applicable laws and regulations;
Tax and accounting requirements;
Court orders;
Subpoenas;
Sanctions requirements;
Regulatory obligations; or
Lawful governmental or administrative requests.
D. Consent
Where legally required, we may rely on consent for specific processing activities.
You may withdraw consent at any time by contacting us. Withdrawal does not affect processing that lawfully occurred before consent was withdrawn.
E. Legal Claims and Prevention of Unlawful Activity
Where permitted by law, we may process relevant information when necessary to:
Establish, exercise, or defend legal claims;
Investigate fraud or unlawful conduct;
Protect the rights or safety of affected parties; or
Address serious compliance or regulatory concerns.
6. COMPLIANCE INVESTIGATIONS AND BUSINESS SUBMISSIONS
Users may submit information concerning matters such as:
Mandatory certification or registration failures;
False, misleading, or unsubstantiated advertising claims;
Product specification or parameter discrepancies;
Customs, country-of-origin, import, or supply-chain concerns;
Environmental, chemical, or material compliance risks;
Restricted products or high-risk commercial activities;
Marketplace policy violations;
Regulatory or product-safety concerns;
Corrective-action requirements; or
Crisis-response or commercial-risk matters.
Submitting information through this website or by email does not, by itself, create:
An attorney-client relationship;
Legal privilege;
A professional engagement;
A fiduciary relationship;
A partnership or joint venture;
An agency relationship; or
An obligation for Pylant Risk to investigate, report, complain, negotiate, or take any action.
A professional engagement arises only when expressly confirmed in writing by an authorized representative of Pylant Risk.
You must not submit information that:
You are not legally authorized to disclose;
Was obtained unlawfully;
Violates another person’s legal rights;
Contains unnecessary sensitive personal information;
Is deliberately false or misleading; or
Is submitted for harassment, retaliation, coercion, or another improper purpose.
We may decline, restrict, delete, or discontinue review of information that appears irrelevant, unlawful, abusive, misleading, improperly obtained, or inconsistent with our business standards.
7. SENSITIVE AND CONFIDENTIAL INFORMATION
Unless expressly requested through an appropriate and secure channel, you should not send us:
Government identification numbers;
Passport or national identification documents;
Bank-account credentials;
Payment-card credentials;
Passwords or account-access credentials;
Medical or health information;
Biometric information;
Highly sensitive personal information;
Unnecessary information concerning children;
Privileged legal communications;
Trade secrets unrelated to the requested service; or
Personal information concerning unrelated individuals.
Ordinary email and general website contact forms should not be treated as fully secure, encrypted, confidential, or legally privileged communication channels.
Please provide only the minimum information reasonably necessary for us to understand and respond to your inquiry.
8. COOKIES AND WEBSITE ANALYTICS
A. Current Use of Cookies
Pylant Risk currently does not use:
Advertising cookies;
Cross-site tracking cookies;
Behavioral advertising technologies;
Meta Pixel;
Google Analytics;
LinkedIn Insight Tag; or
Similar marketing or retargeting technologies.
We do not currently use cookies to create advertising profiles or track visitors across unrelated websites.
B. Framer Analytics
This website is hosted through Framer and may use Framer’s built-in analytics functionality.
Framer states that its built-in analytics functionality does not use cookies and does not generate persistent identifiers for long-term or cross-site tracking.
Framer and its infrastructure providers may nevertheless process limited technical data, such as network, device, security, and page-access information, as necessary to operate, secure, maintain, and measure the website.
C. Essential Technologies
Website hosting, security, networking, or infrastructure providers may use technical storage or access mechanisms that are strictly necessary to:
Deliver requested website content;
Maintain network security;
Prevent fraud or abuse;
Balance traffic;
Preserve technical functionality; or
Diagnose service failures.
Where such technologies are strictly necessary, they may not require prior consent under applicable law.
D. Future Changes
If we later introduce non-essential analytics, advertising, embedded media, chat functionality, marketing pixels, or other technologies that require notice or consent, we will:
Update this Privacy Policy;
Provide additional information where appropriate; and
Implement a consent or preference mechanism where required by applicable law.
9. CONTACT FORMS AND EMAIL COMMUNICATIONS
When you submit a contact form, the information you provide may be processed by:
Pylant Risk;
Framer or the relevant form-hosting provider;
Our email provider;
Cloud or infrastructure providers; and
Other service providers necessary to transmit, secure, store, or respond to your message.
We use contact-form information principally to:
Respond to your inquiry;
Evaluate your request;
Arrange communications;
Maintain appropriate business records; and
Protect against spam, abuse, fraud, and security threats.
Submitting a contact form does not subscribe you to an automated marketing mailing list unless you separately and clearly agree to receive such communications.
10. HOW WE SHARE INFORMATION
We disclose personal information only where reasonably necessary for a legitimate business, professional, contractual, legal, security, or compliance purpose.
A. Service Providers
We may use service providers supporting:
Website hosting;
Domain and network services;
Email and communications;
Cloud storage;
Cybersecurity;
Document processing;
Customer or matter management;
Payment processing;
Accounting; and
Administrative operations.
These providers may process information on our behalf or under their own legally applicable responsibilities.
B. Professional Advisers and Specialists
Where relevant to a matter, information may be disclosed to independent:
Attorneys;
Investigators;
Laboratories;
Certification specialists;
Customs and trade professionals;
Engineers and technical experts;
Regulatory consultants;
Public-relations and crisis-response professionals; and
Other appropriate specialists.
Such parties may act as independent service providers or independent controllers under their own professional, legal, and privacy obligations.
C. Platforms, Authorities, and Counterparties
Where authorized, necessary, or otherwise lawful, relevant information may be disclosed to:
E-commerce marketplaces;
Payment or service platforms;
Certification bodies;
Customs authorities;
Product-safety authorities;
Regulators;
Government agencies;
Courts or tribunals;
Business counterparties; and
Parties involved in remediation, investigation, negotiation, complaint handling, or dispute resolution.
We seek to disclose only information reasonably relevant to the applicable purpose.
D. Legal and Protective Disclosures
We may disclose information where reasonably necessary to:
Comply with law, regulation, court order, subpoena, or lawful legal process;
Respond to a governmental or regulatory request;
Investigate fraud, abuse, threats, or unlawful activity;
Protect legal rights, property, personnel, clients, or business operations; or
Establish, exercise, or defend legal claims.
E. Business Transactions
Information may be transferred in connection with a:
Merger;
Acquisition;
Financing;
Reorganization;
Sale of assets;
Business succession; or
Similar transaction.
Where required, appropriate confidentiality and data-protection safeguards will be applied.
11. SALE, SHARING, AND TARGETED ADVERTISING
We do not knowingly sell personal information for monetary consideration.
We do not currently use personal information collected through this website for:
Cross-context behavioral advertising;
Targeted advertising based on activity across unrelated websites;
Data-broker activities; or
The commercial sale of visitor profiles.
Because we do not currently use advertising or cross-site tracking technologies, we do not currently provide a “Do Not Sell or Share My Personal Information” link.
If our practices change in a manner that creates such an obligation under applicable law, we will update this Privacy Policy and provide any required opt-out mechanism.
12. BUSINESS COMMUNICATIONS AND MARKETING
We may send direct business communications where permitted by applicable law, including where:
You have contacted us;
You have requested information;
We have an existing or prospective business relationship;
Your professional contact information is publicly available and the communication is relevant to your professional role;
We have another legitimate business reason; or
You have provided consent where consent is legally required.
You may request that we stop sending non-essential promotional communications by:
Using an unsubscribe mechanism where provided;
Replying to the message with an opt-out request; or
Emailing contact@pylantrisk.com.
An opt-out request does not prevent us from sending communications that are necessary for:
Existing engagements;
Contract performance;
Payment or accounting;
Security;
Legal compliance;
Dispute handling; or
Other non-promotional business purposes.
13. DATA RETENTION
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected.
Unless a longer or shorter period is justified by the circumstances:
General contact inquiries may be retained for up to 24 months after the most recent substantive communication;
Client, engagement, investigation, compliance, and evidentiary records may generally be retained for up to seven years after the relevant matter is closed;
Contracts, invoices, payment, tax, and accounting records may be retained for the period required by applicable law or normal business-record requirements;
Records relevant to actual or potential disputes, investigations, claims, complaints, or regulatory matters may be retained until the matter and relevant limitation periods have expired;
Security and technical logs may be retained according to the operational and security practices of the relevant hosting or infrastructure provider; and
Minimal opt-out records may be retained as necessary to respect future communication preferences.
Retention periods may vary depending on:
The nature and sensitivity of the information;
The status and complexity of the matter;
Legal, regulatory, and contractual obligations;
Applicable limitation periods;
Evidentiary requirements;
Security considerations; and
The need to establish, exercise, or defend legal claims.
When information is no longer reasonably required, it may be deleted, anonymized, de-identified, or securely archived.
14. INFORMATION SECURITY
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information against:
Unauthorized access;
Unlawful disclosure;
Alteration;
Accidental loss;
Destruction;
Misuse; and
Security incidents.
These safeguards may include:
Access restrictions;
Account-security controls;
Secure service providers;
Data minimization;
Internal confidentiality practices;
Backup and recovery measures; and
Appropriate contractual protections.
However, no website, email system, cloud service, storage system, or internet transmission method can be guaranteed to be completely secure.
You are responsible for:
Selecting an appropriate communication channel;
Avoiding transmission of unnecessary sensitive information;
Protecting your own devices and accounts; and
Confirming the identity of communication recipients where appropriate.
15. INTERNATIONAL DATA TRANSFERS
Pylant Risk operates in an international commercial environment.
Personal information may be accessed, processed, transmitted, or stored in countries other than the country in which it was originally collected, including the United States and jurisdictions in which our:
Service providers;
Clients;
Professional advisers;
Platforms;
Laboratories;
Authorities;
Counterparties; or
Other relevant participants
operate.
Privacy and data-protection laws in those jurisdictions may differ from the laws of your country.
Where required by applicable law, we may use legally recognized safeguards such as:
Contractual data-protection clauses;
Data-processing agreements;
Adequacy mechanisms;
Transfer assessments; or
Other permitted transfer arrangements.
16. YOUR PRIVACY RIGHTS
Depending on your location and applicable law, you may have the right to:
Request confirmation that we process your personal information;
Request access to personal information;
Request correction of inaccurate or incomplete information;
Request deletion of personal information;
Request restriction of processing;
Object to certain processing;
Withdraw consent;
Request data portability;
Opt out of certain marketing communications;
Request information about categories of information collected, used, or disclosed;
Lodge a complaint with an applicable data-protection authority; and
Exercise other rights provided by local law.
These rights are not absolute and may be subject to exceptions.
For example, we may be permitted or required to retain or process information where necessary for:
Legal obligations;
Contract performance;
Fraud prevention;
Security;
Compliance investigations;
Protection of third-party rights;
Freedom of expression;
Confidentiality obligations; or
Establishing, exercising, or defending legal claims.
To submit a privacy request, contact:
Please clearly identify:
Your name;
The nature of your relationship with Pylant Risk;
The right you wish to exercise; and
The information or processing activity concerned.
We may request information reasonably necessary to verify your identity, authority, and relationship to the relevant information.
We will not request more verification information than reasonably necessary.
Authorized agents may submit requests where permitted by applicable law, subject to appropriate proof of authorization and identity verification.
17. CALIFORNIA RESIDENTS
Certain California privacy rights apply only where the relevant California law applies to Pylant Risk and the relevant processing activity.
Where applicable, California residents may have rights to:
Know the categories of personal information collected;
Know the sources and purposes of collection;
Know the categories of recipients;
Request access to specific personal information;
Request correction;
Request deletion;
Opt out of certain sales or sharing;
Limit certain uses of sensitive personal information; and
Receive equal service for exercising privacy rights.
Pylant Risk does not knowingly sell personal information for monetary consideration and does not currently engage in cross-context behavioral advertising through this website.
Nothing in this section is intended to represent that every provision of the California Consumer Privacy Act or California Privacy Rights Act necessarily applies to Pylant Risk.
18. EUROPEAN ECONOMIC AREA, UNITED KINGDOM, AND SWITZERLAND
Where the GDPR, UK GDPR, Swiss data-protection law, or another applicable European data-protection law applies, individuals may contact us regarding:
The identity of the controller;
The purposes and lawful bases for processing;
Categories and sources of personal information;
Recipients or categories of recipients;
Retention periods;
International data transfers;
Applicable safeguards; and
Available data-protection rights.
You may also lodge a complaint with the competent data-protection authority in your country or region.
Before filing a complaint, you may contact us so that we have an opportunity to address the concern directly.
Nothing in this Privacy Policy limits any right that cannot lawfully be waived.
19. CHILDREN’S PRIVACY
This website and our services are intended for businesses, professionals, and adults.
They are not directed to children.
We do not knowingly collect personal information through this website from children under 13.
Individuals under 18 should not submit personal information through the website without appropriate authorization from a parent, guardian, or other responsible adult.
If we learn that personal information concerning a child was collected in violation of applicable law, we will take reasonable steps to delete, restrict, or otherwise appropriately address the information.
20. THIRD-PARTY WEBSITES AND SERVICES
This website may contain links to:
Third-party websites;
E-commerce platforms;
Regulatory databases;
Government authorities;
Professional advisers;
Social-media platforms; or
Other external services.
We do not control the privacy, security, content, availability, or data-processing practices of those third parties.
The inclusion of a link does not mean that we endorse or accept responsibility for the third party’s practices.
You should review the privacy policies and terms of third-party services before providing them with personal information.
21. AUTOMATED DECISION-MAKING AND ARTIFICIAL INTELLIGENCE
We may use software, automated tools, or artificial-intelligence-assisted systems to support activities such as:
Research;
Translation;
Document organization;
Data extraction;
Preliminary screening;
Pattern identification;
Evidence review;
Drafting assistance;
Fraud detection; or
Risk analysis.
Such tools may assist our personnel but do not necessarily determine the final outcome of a matter.
Unless separately disclosed, we do not use personal information collected through this website to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
Where appropriate or legally required, material decisions are subject to human review.
Users should avoid submitting unnecessary confidential, privileged, or sensitive information for processing through general communication channels.
22. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in:
Our services;
Our business operations;
Our website;
Our technology providers;
Our data-processing practices;
Applicable laws or regulations; or
Security and compliance requirements.
The revised Privacy Policy will be posted on this page with an updated “Last Updated” date.
Where required by applicable law, we may provide additional notice of material changes.
Your continued use of the website after an update does not waive any consent or other legal requirement that applies under applicable law.
23. CONTACT INFORMATION
Questions, concerns, and privacy requests may be directed to:
Pylant Risk
Operated by Pylant Advisory LLC
Email: contact@pylantrisk.com
Website: www.pylantrisk.com
Business address: 30 N Gould St, Ste N, Sheridan, WY 82801, United States
